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HANCOM WITH 


We Empower Your Investigation! 


HancomWiITH 


We Empower Your Investigation! 


As the importance of the forensic investigator increases alongside the rapid development of new technology, HancomWITH 


empowers investigative agencies around the world by maintaining the foremost optimal solution for acquiring digital evidence. 


MD-Series is an integrated digital and mobile forensic solution that combines the latest in forensic technology developed by 


HancomWlITH. In addition to our already-comprehensive support for mobile evidence acquisition, we are actively researching and 


developing new forensic solutions for all the newest technology, including Drones, Al speakers, and Smart TVs. 


With over 16 years of mobile forensic research experience and continuous R&D with our overseas partners, HancomWITH provides 


customer-proven technology, highly reliable technical support, and forensic training to investigative agencies around the world. 


Through our efforts to provide the world’s law enforcement professionals with the best in digital forensic solutions, HancomWITH 


strives to create a healthier, fairer, and more intelligent tomorrow. 


I BUSINESS AREA 


MD-SERIES 


Complete line of mobile and digital 
forensic products for data extraction 
and analysis 


Training & Certification 


Mobile forensic training courses for 
investigators and auditors 


I OUR CLIENT 


Leicestershire Police 


Mobile & Digital Forensic Service 


Mobile phone, computer, video, 
document, loT forensic service for 
the law enforcement agencies 


HANCCO 


HANCOM WITH 


Digital Forensic Lab Solution 


Fully equipped with digital forensic 
laboratory solution 
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36,000 PIECES 


OF MOBILE EVIDENCE 
PROVIDED BY OUR SERVICES 
ANNUALLY 


15,000 MODELS 


(SMARTPHONE) 


SUPPORTED BY OUR 
SOLUTIONS 


2,000 Apps 


FOR ANDORID AND iOS 
SUPPORTED 


59 


200 AGENCIES 


USE OUR SERVICES 


investigation situation 


daadaa 


Provides complete mobile and digital 
forensic solution that fits various 


Covers a wide range of global mobile 
phone models and apps 


Specialized in Asian manufacturers’ 
device and diverse apps 


Forensic purpose built hardware 
products for JTAG and Chip-off 


Mobile forensic package for field 
investigation and academic training 


16 YEARS 


OF RESEARCH EXPERIENCE 
IN MOBILE FORENSICS 


9 Patents 


HancomWITH's 
PATENTED INNOVATIVE 
TECHNOLOGY 


New digital forensic software solution; 
Cloud/Video/loT/Drone/Vehicle 


Intuitive and User-friendly UI 


Online package updates and 
subscription of new devices and the 
latest app version 


In-depth mobile forensic training & 
certification courses 


Experienced in mobile forensic laboratory 
establishment and management 
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MD-SERIES 


PRODUCT OVERVIEW 


Complete mobile and digital forensic product line for data extraction and analysis with integrated cutting-edge mobile 
forensic technology, supporting any type of mobile device 


I Mobile Forensic Software 


MD-LIVE 


Mobile forensic software solution for live data extraction and analysis from 
smartphones which supports the first responders 

MD-NEXT 

Mobile forensic software for performing data extraction on Smartphone, Feature 


phone, Drone, Smart TV, Wearable device, loT device, USIM card, SD memory card, 
JTAG, and Chip-off memor 


Mobile forensic software solution for recovering, analyzing, and reporting on 
extracted data 


MD-BOX 


Mobile forensic hardware solution for extracting data directly from the motherboards 
of mobile devices through the JTAG interface 


MD-READER 


Mobile forensic hardware solution for extracting data directly from 

a detached memory chip pulled from the motherboard of a mobile phone 
MD-CARRIER 

Various tool portable package for JTAG/Chip-off 


MD-CABLESUITE 


Smartphone cable bag and FPCB Cable suite 


MD-MR 


Package of forensic hardware devices for physically removing the memory chips 
from the motherboards of mobile phones when performing Chip-off forensics 


| Digital Forensic Software 


MD-CLOUD 


Digital forensic software for extraction and analysis of cloud-based account data 


MD-VIDEO 


Digital forensic software for video data preview, recovery, and analysis of video 


| Mobile Forensic Packages 


MD-RUGGED 


Rugged forensic package for performing portable forensic investigation at the crime 
scene 


MD-PORTABLE 
Portable mobile forensics package solution for performing live data acquisition and 
analysis in the field 


MD-ACADEMY 


Academic training package, containing all the necessary equipment for mobile 
forensic education 


| MD-SERIES Selection Guide 


Device type Extraction HW Extraction SW Analysis SW 
Digital device 
Data extraction and analysis for 


| | 
Smartphone 
MD-LIVE 
Live data extraction and analysis in the field 
Smartphone, loT device, Drone and Embedded HW 
JTAG board 


MD-BOX MD-NEXT 
Data extraction from board with JTAG interface 
Chip-off memory 
Data extraction from physically removed MD-READER 
flash memory 
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MD-LIVE n 


MD-LIVE is a mobile forensic solution for quickly performing logical extraction and data analysis on live mobile devices. It also 
supports a number of legal compliance features such as the selective acquisition of evidence to ensure a suspect's right to privacy, 


as well as mirroring and recording the suspect smartphone's display during the forensic process. MD-LIVE also supports the use of a 
separate camera for recording the forensic process externally. l KEY FEATURES 


Mobile forensic software for on-the-spot investigation performing live extraction and analysis on mobile devices 


SPECIFICATION 


| PRODUCT HIGHLIGHTS 


Selective extraction and analysis of evidence data 

- Data unrelated to the case can be excluded from selection and 
analysis 

inimizing the extraction of unnecessary data reduces the time 
spent on the site and protects the privacy of those involved 

- Important apps can be scanned based on time and frequency of use 


Acquisition Only feature 

- Depends on the situation at the crime scene, the investigators 
can proceed with data acquisition first and then do data analysis 
afterward. 


Data restoration 
- Multimedia data from Messages, Contact, Call records, KakaoTalk, 
Facebook Messenger, WeChat, Telegram, WhatsApp can be restored 


Advanced data filtering and Search options 
- Organize your data more easily with filters that vary by app 
- Enable to search keywords in all analyzed results 


Processed evidence data presented just like a real smartphone 
display 
- The view interface is themed and presented as a smartphone app, 
allowing users to quickly and intuitively identify evidence data 


Various data viewer options 
- Users can view evidence files such as photos, videos, audio, 
documents, maps, and website browsing history directly in the 
software 
- View only selected items that are under investigation 


Mirroring and remotely controlling smartphone display 
- The smartphone displays mirroring and the remote-control feature 
can be used to circumvent a broken display or to prevent any 
unwanted operations on the device 
- The mirrored display can be also captured and recorded as evidence 


MD-LIVE software screen recording 
- The PC screen recording feature can record forensic processes 
performed in MD-LIVE for reproduction and verification purposes 


Device battery level check feature 
- Supports to check the battery level of the connected target device 
when data acquiring 


Easy and automated process 
- Automated post-extraction analysis feature makes investigation 
process much faster 


External standing camera (Option) 
- The optional standing camera offered for taking photos of evidence 
device and its display or for recording the investigation procedure 


Hash verification 
- Extracted files are hashed and compared against the registered hash 
set 


Report generation 
- PDF, Excel, and SQLite DB 
- Saving reports and dump images to USB/DVD 


System requirements 


Product components 


OS: Windows 8/10 (All 64 bit) 
CPU: i5 or faster 
RAM: 8GB or above 


MD-LIVE Installation Software (USB/Online) 
USB Dongle Key 1 EA 
Warranty 1 Year 


= Mobile forensic software solution for on-the-spot investigation and forensic triage = Mirroring, recording, and capturing smartphone display Storage: 256G or morg. 
; a i ear aea l that 2i i Display: 1200x700 or higher 
m The best forensic tool for acquiring data from witnesses'or victims'smartphones = High-speed analysis engine and automated steps allows minimal work time 
m Selective acquisition of data for privacy protection m Provides an external camera for recording the forensic process (for auditing or USB: 2 or more USB 2.0 ports 
= Advanced data filtering and Keyword Search options legal compliance purposes) Microsoft.Net Framework 4.6.2 
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MD-NEXT 


MD-NEXT is a forensic software solution for data extraction on a wide variety of mobile and digital devices. It supports both physical and 
logical extraction methods for Android, iOS, Windows OS, TizenOS, and other mobile operating systems. 


Mobile data extraction-software for Smartphones, Feature phones, Drones, SmartTVs, Wearables, loT devices, 


kk k T 


USIM cards, SD memory cards, JTAG boards, and Chip-off memory 


SPECIFICATION 


| PRODUCT HIGHLIGHTS 


= Data extraction from smartphones, feature phones, loT devices, smart TVs, drones, 
chip-off memory, and JTAG boards 

= Powerful extraction tools for devices from Asian manufacturers (Samsung, LG, and 

Chinese brands) 

Supports all physical extraction methods - Bootloader, Custom Image, ADB Pro, MTK, QEDL 


Supports all logical extraction methods - Android Live, iOS full filesystem, MTP 


m Unlock latest Samsung and Chinese phones (Oppo/Vivo/Huawei/Xiaomi) 


® iOS keychain extraction 


| KEY FEATURES 


The perfect data extraction tool for diverse mobile and digital devices 
- Data acquisition for various global smartphone manufacturers (Samsung/ 
Apple/LG/HTC/ZTE) models 
+ Chinese manufactured devices (Huawei/Xiaomi/Oppo/Vivo, etc.) 
- lol device, Al Speaker, Drone, and Smart TV 


Advanced physical extraction 
- Supports Bootloader, Fastboot, MTK, QEDL, Custom Image Android Rooted, 
iOS Physical, DL, JTAG, Chip-off, SD Card, Removable Media 
- ADB Pro extraction which supports data acquisition using vulnerability 
attacks from Android-based devices 
+ JTAG pin map viewer and connection scanning with AP 


loT device data extraction 
- Smart Band - Fitbit 
+ Smart Watch - Apple Watch(iOS), Galaxy Gear(TizenOS) 
- SmartTV - Samsung(TizenOS), LG(WebOS) 
- Al Speaker - Amazon Echo, Google Home, Kakao Mini, Naver Clova, KT Giga 
Genie, SK NUGU 
- Drone - DJI (Phantom, Mavic), Parrot, PixHawk 


Advanced logical extraction 
- Android Live, MTP iOS full filesystem Backup, Vendor backup protocol, Local 
backup, USI 


Supports extraction and unlocking of the latest Asian phone 
- Physical extraction through all lock bypass (KNOX, FRP/OEM, Screen Lock): 
Samsung Galaxy S/J/A/Note series 
- Unlock screen: Samsung Galaxy S/J/A/Note series 
* ADB Pro physical KNOX bypass - Samsung Galaxy S/J/A/Note series 
- Vendor Backup protocol extraction - Samsung, LG, Huawei 
* Local backup extraction - Huawei, Xiaomi, Oppo, Gionee 
- Physical extraction for Japanese manufacturer model - Sharp, Sony 


Supports the latest iPhone logical extraction 
* iOS keychain 
- iOS full filesystem 
* Logical extraction for iPhone up to XS/XR model 
- The decryption of backed up data for the latest version of the iOS device 


BANTO 


Useful extraction options 
+ User-defined extraction for unlisted models using pre-defined methods 
- Selective extraction by the partition, file, category, app for privacy 
protection 
- Auto-recognition and decryption of partition table and encrypted partition 
* Automatic firmware restoration and retrial after restoration failure 
- Pause/Resume feature 
+ Merges multiple image files - MDF and binary file 
- Creates MDF file from PC backup 


Assures evidence data integrity 
+ Write-protection for every piece of evidence 
- Supports ten different hash algorithms, including MDS, 
SHA1/224/256/384/5 12, RIPEMD128/160/256/320 


Support multiple device extraction 
- Supports both simultaneous and sequential extraction 


Supports diverse physical data reading hardware 
- JTAG Reader (MD-BOX) 

emory Chip Reader (MD-READER) 

* SD Memory Reader/USIM Reader 


Data preview and saving features 
- Extraction data preview- Hex viewer 
* Sound alarm and TTS alarm for extraction status change 


User-friendly and intuitive user interface 
Intuitive graphical user guide for each extraction method 
- Features 'Recently Selected Models’ List 


Report generation 

+ Extraction information - Hash value, Time, Method and Filename 
- ‘Extracted File List' generation with a hash value of each file 

- Generates ‘Witness Document’ 


System requirements 


Product components 


OS: Windows 8/10 (All 64 bit) 
CPU: i5 or faster 

RAM: 4GB or above 

Storage: 1TB or above 
Display: 1024x768 or higher 
USB: 2 or more USB 2.0 ports 
Microsoft.Net Framework 4.6.2 


MD-NEXT Installation Software (USB/Online) 
USB Dongle Key 1 EA 
Warranty 1 Year 
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MD-RED 


MD-RED is a forensic software solution for recovering, decrypting, visualizing, performing analytic data mining, and reporting evidence data that's been 
extracted with MD-NEXT or another analogous extraction tool. The analysis results output by MD-RED can be exported as forensic reports for crime and 


accident investigations. In addition, as a result of our continuous ongoing research, MD-RED's mobile app analysis engine is constantly being updated l KEY FEATU RES 
with support for analyzing the latest apps. 


Supports wide variety of mobile operating systems and devices Visualization of analyzed data 
- Feature phones, Smartphones and various other digital devices * Map viewer for GPS and cell tower location data 
- iOS, Android, Windows, TizenOS and other mobile operating systems - Offline / Online map (Region / Country / City view levels) 
Parsing and recovery of various filesystems * Timeline view be sie seat 
- FAT12/16/32, exFAT, NTFS, ext3/4, HFS+, EFS, YAFFS, FSR, XSR, F2FS, VDFS, * Linkviewer (social relationship visualizer 
XFS filesystems “Chat viewer ; es 
- Data carving of unused areas - Web browser view (for internet browsing history) 
Supports analysis of mobile data over 2,000 popular mobile apps Advanced data filtering options , : 
ultimedia files taken by device camera . Filtering bya variety of properties such as filesystem, signature, and time 
- Call logs, Address book information, SMS/MMS messages, emails, Memos, * Dynamic filtering operators, sorting, and grouping 
and Internet history - Search by regular expression ae 
- Social networking, maps, navigation, banking, health, and lifestyle apps Character search E Supports to search similar words 
- Detection of Anti-forensic apps, and hidden apps * Keyword registration 
i 3 , - Bookmarking selected data 
Supports decoding screen lock and password information od i > 
* Decoding unlock patterns, PINs, and passwords New digital device analysis PUO 
- Brute force through GPU acceleration + Drone data analysis - Flight history, Multimedia data, Supports 
- iPhone keychain data analysis — Credential (collected from iOS keychain, manufacturer DJI Parro/PixHawk — 
iOS, App information) can be exported and analyzed by MD-CLOUD + loT device data analysis - Al Speakers, Smart TV, Car Navigation 
Data decryption Python scripting IDE for user-defined analysis 
- Identifying encrypted documents * Includes a Python script editor ; ; 
* Supports decryption of chat messages, emails, files, and other app data , ron a ing, executing, and debugging code and includes 
Deep analysis on popular messenger apps Sad 
a ae - Deserialization, decryption, and recovery of data Case management and hash value verification 
2 O ontio nna see: sea sen - Skype, Facebook messenger, Telegram, Wickr, QQ, KakaoTalk, Line, Zalo, * Various case management features 
i | 5 Viber, Snapchat, and many more * Grouping extraction images ; 
- WhatsApp — Multiple backup file analysis - Hash value verification on a per-image basis 
+ WeChat - Multiple account analysis, rainbow table analysis Maximized performance 
Multimedia data recovery and analysis - High speed analysis achieved through multi-core CPU/GPU parallel processing 
- Supports frame recovery for deleted/damaged video files + Supports running multiple instances of the program (i.e: one instance for 
- Supports the use of Reference Data Set (RDS) for excluding over 9.8M each open case) ; 
known unusable images from analysis result data i Analysis status alarm — Pop-up message will let user know when ; 
- Supports audio file conversion (From AMR/AUD/OCP/SILK to MP3/AMIR/WAV) orensically important data and history are found (ie. Initialization history, 
- Supports playing QCP files and SILK-encoded audio Data hidden apps, Parallel space) 
Log analysis Report generation 
- Supports analysis of various logs: media, search word, system, and network i Ai a e dia 
Bluetooth, WiFi, Cell t i 
e ( noa S owens) - Automatic report generation (PDF, Excel, HTML, XML, SQLite DB formats) 
Sacin relationship analysis TORPA i - Supports 3rd party reporting formats like Nuix and Relativity 
' e Basic/Advanced Ie analyzing nge Me phones - Bundling feature - Bundle generated reports/outputs (exported folder, 
* Call history, messenger, and email communication data analysis etc) into MDF file 
Filtering by app, time period, contact(s), and type(s) of communication 
a A : l 7 ; a 7 : 7 * Community analysis 
Mobile data analysis software for recovering, decoding, decrypting, visualizing, and reporting evidence data from mobile devices - Relationship visualization and automatic re-organizing 
Embedded data viewers 


* View extracted data and source information directly in-application 
- SQLite databases, HEX, PLists, Documents (Text, XML, PDF, MS Office), 


SPECIFICATION oan Ato 


System requirements Product components 
l PRODUCT H IGH LIG HTS OS: Windows 8/10(All 64 bit) MD-RED Installation Software (USB/Online) 
CPU: i7 or faster USB Dongle Key 1 EA 
: ; ; RAM: 8GB or above External HDD for WeChat analysis 

m Supports analysis and recovery for a number of filesystems and over = Supports drone and icy device analysis Strand TB orabove Warranty 1 Year 

2,000 mobile apps m Supports post-analysis data visualization Display: 1024x768 or higher 
m Supports decryption of encrypted instant messaging apps m Includes built-in Python script editor for custom application analysis USB: 1 or more USB 2.0 ports 
m Provides quick updates and rolling support for new versions of apps Microsoft.Net Framework 4.6.2 


= Supports social relationship analysis 
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MD-CLOUD 


MD-CLOUD is an intuitive digital forensic software tool for extracting and analyzing data from the cloud. It supports a broad range of 
cloud services as well as a variety of other data sources, such as Email, loT devices, and social media accounts. 
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Digital forensic software for extraction and analysis of cloud-based account data 


SPECIFICATION 


| PRODUCT HIGHLIGHTS 


= Supports extraction from global cloud services such as Google and 
iCloud 

= Supports extraction of Cloud-based loT device data 

= Supports extraction from cloud services based in East Asia, such as 
Baidu and Naver Cloud 

m Provides automatic evidence-tagging feature for intuitive searching 


= Authenticates via ID and password, two-factor authentication, Captcha, and 
token credential information found locally on smartphone images, such as 
iOS Keychain 

m Includes automated web scraping tool for recursively capturing public webpages 

m Natively integrates with MD-RED 


| KEY FEATURES 


Supports a wide variety of cloud services 
- Google, iCloud, Samsung Cloud, Naver Cloud, Evernote, One Drive, 
Baidu 


Supports email extraction 
* POP3 and IMAP. as well as specific support for Gmail and Naver Mail 


Supports extraction from social media services 
* Current support for Twitter and Tumblr, with Facebook support under 
active development 


Specialized in East Asian cloud services 
- Baidu Cloud in China 
- Naver Cloud in South Korea 


Acquisition of cloud-based loT device data 
- Al Speakers and Smart Home equipment 
* Supports authentication via both public and unofficial APIs 


Supports various authentication methods 
* ID and Password 
- Captcha image tests 
- Two-Factor Authentication messages 
* Credential data pulled from smartphone dump images (such as iOS 
Keychain) 


Provides automated web capture feature 
- Automated web-crawler capable of recursively extracting from a 
target web page 


Real-time extraction progress monitoring 
- Displays the progress of ongoing extraction jobs in real time, from 
zero to one hundred percent 


ASCO 


User-friendly interface 
- Features a simple, intuitive, and effective user experience that 
warrants little training 


Native MD-RED integration 
* Imports credential information found in suspect smartphone images 
that have been analyzed in MD-RED 


Intuitive 'Evidence Tagging’ based search feature 
- Automatically tags and categorizes data as it's extracted from the 
cloud so that it can be quickly searched, grouped, and organized. 


Built-In data preview 
- Supports previewing any selected image, video, document, web 
page, email, and many more 


Supports filtering by date range and file type 
- Allows users to limit the results of their analysis only to the time 
period and file types relevant to their case 


Hash based data integrity assurance 
- Guarantees the integrity of the evidence data through powerful hash 
algorithms such as MDS and SHA256 


Report generation 
- Provides report generation tool that supports both PDF and Excel 
formats 


System requirements 


Product components 


OS: Windows 8/10(All 64bit) 

CPU: i5 or faster 

RAM: 4GB or above 

Display: 1024x768 or higher 

USB: 1 or more USB 2.0 ports 

Network: Internet connection via wired or wireless LAN 


MD-CLOUD Installation Software (USB/Online) 
USB Dongle Key 1 EA 
Warranty 1 Year 
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MD-VIDEO 


MD-VIDEO a digital forensic software tool for extracting and recovering video data directly from damaged video files as well as media 


We Empower Your Investigation! 


storage devices such as disks and memory cards. 
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Digital forensic software for video data preview, recovery, and analysis of video 


SPECIFICATION 


| PRODUCT HIGHLIGHTS 


= Supports preview, recovery, and analysis of video data from CCTVs, vehicle dashboard cameras, camcorders, and smartphones 


= Supports various DVR filesystems, video formats, and video codecs 
= Supports regenerating videos via recovered video frames 


= Supports Al-based analysis such as object detection, video compression, and filtering with various criteria 
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| KEY FEATURES 


Video data forensics from CCTVs, car dashboard cams, smartphones, and 
other media storage devices 


- Supports IP-CCTVs from a variety of global manufacturers as well 
as key manufacturers’ vehicle dashboard cameras, smartphones, 
desktops, servers, cameras, camcorders, drones, wearable devices, 
and embedded systems 

3 types of video data input 


- Mounted storage devices, such as physically connected hard disks 

- Binary disk images, such as DD, E01, BIN, and MDF formatted images 

- Damaged files that contain video stream inside 
3 types of video recovery 

- Filesystem recovery 

- File signature-based recovery (DAV, MP4, MOV, MKV, MPEG, SSF, AVI, ZAV, PS) 
- Video frame recovery (H.264, H.265, MPEG-4, M-JPEG) 

Various filesystems 

* Filesystem auto detection filesystem auto-detection 


+ FAT 12/16/32, NTFS, exFAT, HFS+, EXT3/4, TAT16, HIKVISION, DHFS4.1, 
XFS, F2FS, VDFS 


- Supports proprietary DVR filesystems such as HikVision, Dahua, 
Zhiling, Samsung, Bosch, Honeywell, Sony, Panasonic, etc. 
Various video codecs 
- H.264, H.265, MPEG4, M-JPEG 
- H.264 resolution adjustment for recovery 


- Supports HEVC (H.265) recovery and media playback for iOS 11 and 
above models 


- Sampling codec from the video file and smartphone codec 
- Custom, user-defined codec parameter settings 
Video file scanning 
* Frame and file format scanning 
- Deleted and damaged file scanning 
Recovery of video frames 
* Capable of reconstructing frames of video files 
- Extracting image frames with pictures 
* Thumbnail preview and image view 
Audio file recovery 
- SILK format audio file recovery 


Selected partition recovery support 
- Auto-scanning of partitions 
* Selecting and recovering specific partitions 


Multi-core CPU/GPU acceleration 

- Accelerated recovery with multi-core CPU 

- Support for accelerated object detection with multi-core GPU in active 

development 

Bookmarking, Filtering, and Indexing 

- Supports bookmarking for examination and creating reports 

- Provides features for organizing, filtering, and indexing files/frames 
Time information acquisition 


+ Acquires time information for image files through metadata analysis of 
each frame 


Built-in video player 
* Supports multi-channel video playback 


- Provides control over play speed (1/10X, 1/2X, 1X, 2X, 4X, 8X) 


* Supports more than 300 image formats (MP4, AVI, MKV, WMV, MPEG, etc.) 
- Various DVR video file formats (DAV, ZAV, SSF) 


Data viewers 


+ Frame picture viewer 
~ Hex viewer 
- File viewer 


File/Format converter 
- Export original or converted files 


Supports multi-channel video storage separately when extracting files 
* Converting recovered frames to JPG and PNG format 

- Converting video files to AVI and MP4 format 

* Converting audio files to MP3 and AMR format 


Video Analytics 


- Al-Based Object Detection - More than 80 kinds of objects can currently 
be recognized 


Time Filter - Provides time offset setting for viewing the detected objects 
in the desired time zone as well 


- Object Filter - Provides filter for the user to view only relevant objects 


Video Contraction - Capable of shortening a long video by extracting only 
sections of the video that contain motion 


Report generation 


- Automatic report generation and exporting as PDF and Excel formats 


System requirements 


Product components 


OS: Windows 8/10 (All 64 bit) 

CPU: i7 or faster 

GPU: 1 or more multi-core GPU card for acceleration 
RAM: 32GB or above 

Storage: 8TB or more 

USB: 2 or more USB 2.0/3.0/3.1 ports 

Microsoft.Net Framework 4.6.2 


MD-VIDEO Installation Software (USB/Online) 
USB Dongle Key 1 EA 
Warranty 1 Year 


MD-VIDEO 
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MD-BOX 


MD-BOX is a forensic hardware solution for extracting data directly from a phone's motherboard through the JTAG interface. In cases 
where the motherboard of a mobile device has survived despite external damage to the phone, a forensic examiner can use MD-BOX to 


connect to it through the JTAG interface. l KEY FEATU RES 


Data extraction from the board with JTAG interface 
- Forensic hardware for reading data directly from the main board of the mobile device using JTAG interface 


Advanced extraction features 
- Auto-scanning of partitions 
- The selected partition extraction 
- Extraction without reference voltage 
- DMA (Direct Memory Access) type extraction 
* Resumption of extraction from the halted point 


Mobile CPU support 
SMO6XXX, MSM7XXX, APQ, Exynos, OMAP, Cortex-A, Xscale series CPU family 


Excellent extraction performance 
ax. IMB/sec extraction performance 


Assurance of evidence data integrity 


- Write-protection of the evidence data 
- 10 hash algorithms such as MD5 and SHA256 


JTAG cable support 
- FPCB connector cable sets, MD-CABLESUITE 
- Manual connection by soldering work 


Image file save using MD-NEXT 
- Saves data as MDF image file with MD-NEXT software 


Mobile forensic hardware for extracting data directly from mobile phone motherboards through the JTAG interface 


Product components Hardware specification 
SPECIFICATION MD-BOX Hardware 1 EA CPU: ARMO 
Probe connector 1 EA RAM: 64Mbytes 
| PRODUCT HIGHLIGHTS Power adapter 1 EA Input Voltage: DC 5V/2A 
USB cable 1 EA JTAG Clock: 1KHz ~ 50 MHz 
= Physical extraction for the mainboard with JTAG = Write protection and evidence integrity a S a A 
= Applicable to the damaged mobile device = Data image file save with MD-NEXT FPCB Cable Suite (Option) Size: 75 x 120x isim i 


= Various Mobile CPU support 
= Faster and robust extraction feature 
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MD-READER 


MD-READER is a forensic hardware solution for extracting data directly from flash memory extracted during Chip-off forensics. After 
mounting the flash memory into one of MD-READER's memory sockets, examiners can extract data through the Chip-off feature provided 
ae | KEY FEATURES 


Data extraction from Chip-off flash memory 
- Data extraction from the flash memory of mobile phones or digital devices heavily damaged by fire, water, or external shock 


Supports 10 types of eMMC/eMCP memory sockets 
eMMC memory sockets (5 Types) 

* BGA153 eMMC - 11.5x13x0.5mm 

- BGA169 eMMC - 12x16x0.5mm 

- BGA169 eMMC - 14x18x0.5mm 

- BGA100 eMMC - 14x18x1.0mm (Option) 

- BGA136 eMMC - 10x10x0.5mm (Option) 

eMCP memory sockets (5 Types) 

* BGA186 eMCP - 12x16x0.5mm 


- BGA221 eMCP - 11.5x13x0.5mm 

- BGA162 eMCP - 11.5x13x0.5mm (Option) 

* BGA254 eMCP - 11.5x13x0.5mm (Option) 
1 


- BGA529 eMCP - 15x15x0.5mm (Option) 


Universal SD memory card socket 
- SD Card, Mini SD Card, Micro SD Card 


Selected partition extraction 
- Auto-scanning of partitions 
- Extraction for selected partition 


Excellent extraction performance 
- Max. 12MB/sec extraction performance 


Assurance of evidence data integrity 
- Write-protection of the evidence data 
- 10 hash algorithms such as MD5 and SHA256 


s 
w 
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Mobile forensic hardware for extracting data from Chip-off memory na X eine patente ee 
* Saves data as Image Tile wit! z software 


Product components Hardware specification 
SPECIFICATION 


MD-READER Hardware 1 EA CPU: Samsung S5PV210 
l PRODUCT H IGH LIG HTS Sockets of eMMC or eMCP 5 EA (5+ sockets as option) RAM: DDR256M 
Universal SD memory card socket 1 EA Memory: NAND 512M 
= Supports data extraction of Chip-off flash memory = Excellent extraction performance Power adapter 1 EA Input Voltage: DC 5V 
= Supports heavily damaged mobile phones or digital devices m Write protection and evidence integrity an ee (eer er modek side RESTO 
= Supports 10 types of eMMC/eMCP memory sockets = Data image file save with MD-NEXT Way: ve 
a 


Supports universal SD memory card socket 
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MD-CARRIER 


Portable package with various tool for JIAG/Chip-off 


MD-CABLESUITE 


Smartphone cable bag and FPCB cable suite 


Package basic components 


NO Description Spec Pcs. NO Description Spec Pcs. 

1 Solder wire core 500g, With holder 1 2 Driver set2 6pcs (Precision) 

2 PCB Cleaner 300ml 1 3 Stripper 3500E 

3 Soldering iron High frequency 1 4 Nipper MN100 

4 Evidence storage box 14x14mm 3 5 Soldering tip 101-T-l 

5 Solder Wick Chemtronics 80-3-5 3 6 Opener Hera(White) 2 
6 Dispenser 180ml 7 Pincette 1-SA 

7 Flux UP-78 8 Flux brush Series 2500 

8 Wire 34 34AWG 9 Cleaning brush 196mm 

9 Wire 30 30AWG 20 JTAG Connector PHO1 20 
10 Phone tester HIOKI 21 Work plate ESD Free 1 
11 Driver set1 7pcs 22 Carrier bag Aluminum 


SPECIFICATION 


a Optional package for MD-BOX & MD-READER 


= Warranty : 1 year 
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Package basic components 


[FPCB Cables for Phone Model] 


SHV-E120S(SHV-E120L,SHV-E160S,K) 


NO FPCB Cable Phone Model NO FPCB Cable Phone Model 
1 -——_ SHW-M250L 5 p LG-LU6800(LG-SU760) 
2 -— SHW-M250K 6 b —- LG-LU6200 
3 p — SHV-E160L 7 | SHV-E110S 


SPECIFICATION 


= Easy connection without wiring 
a Optional package for MD-BOX 
= Warranty: 1 year 
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MD-MR 


MD-MR is a forensic hardware package solution for detaching memory from the motherboard of a mobile phone or other digital device. When a device 
has sustained damage from physical force, fire, or water exposure, MD-MR can perform Chip-off forensics. MD-MR includes five flash memory sockets for 


MD-READER, a heat blower, a soldering station, a fume extractor, and a microscope along with optional components such as the mobile device dryer, l KEY FEATU RES 
rework system, and mobile device safety box 


MD-MR Standard devices MD-MR Optional devices 
- 5 flash eMMC/eMCP memory sockets for MD-READER Rework Station 
- Heat blower for disassembling work - Rework station for small PCB (BK-350S) 
* Supports for manual soldering - Optimized for mobile phone rework 


- Fume extractor for soldering work : ; 
* Microscope - Zoom stereo, 361 80K Lighting equipment Mobile device and PCB Dryer 
- Digital microscope with HDMI/USB for PCB inspection * Dryer for PCB board and small digital device (RG-202) 
- Convective drying maintains a stable temperature inside 
- Safe circuit to prevent the override of the heater 


Mobile device Safety Box 


- Mobile device storage for smartphone and tablet 
- Battery charge during storage 

- Sterilization 

- Digital locking system 


Standard devices 


Ko 
hhh 4 á Pi 
> 5 flash > Heat blower for > Soldering Station > Fume Extractor > Microscope > Digital microscope 
memory sockets dissemble work with HDMI/USB 
Optional devices 
L 
Mobile forensic hardware package for detaching memory from motherboards of mobile phones and other digital devices 
> Rework station > Mobile device dryer > Mobile device Safety Box 

S P ECI F | CATI O N Package basic components Package optional components 
l PRODUCT HIGHLIG HTS 5 flash memory sockets for MD-READER 1 SET Rework station 1 EA (Option) 

Heat blower for disassembling work 1 EA Mobile device dryer 1 EA (Option) 
a Essential devices for manual memory removal Soldering Station 1 EA Mobile device safety box 1 EA (Option) 
= Optional automatic rework machine, mobile device dryer, and safety box Fume Extractor EA Warranty 1 Year 


Microscope with lighting 1 EA 
Digital Microscope for PCB inspection 1 EA 
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MD-RUGGED 


MD-RUGGED supports professional on-site investigation. Data can be both extracted and analyzed with MD-RUGGED directly at the 
crime scene. 


| KEY FEATURES 


Supports data extraction at the laboratory level 


- Supports all logical and physical extraction capabilities at the field 


Supports temporary command center 


- Workable as a mobile forensic control tower at the very spot where the accident took place 


External camera for Chain of Custody 


- Photographing evidence and recording of investigation process with external camera for Chain of Custody 


Supports all the necessary forensic accessories 


- A USB cable, SD reader, USIM reader, USB hub, External camera, and External HDD 


Package components Laptop specification 
Rugged Carrier 1 EA OS: Windows 8/10 (All 64bit) 
Rugged mobile forensic hardware and software package for frontline investigators D-NEXT/MD-RED Installation Software (USB/Online) CPU: i7 or faster 
USB Dongle Key 1 EA RAM: 8GB or above 
High-Performance Laptop 1 EA SSD: 1TB or more 
5 Types of smartphone cables (5, 8, 20, 30, C-typed pin) Display: 1024x768 or higher 
S D -CI HI CATI O NI HD External Camera 1 EA USB: 2 or more USB 2.0/3.0/3.1 ports 
External HDD 1 EA (for Wechat multi-account analysis) Microsoft.Net Framework 4.5 
SD Reader 1 EA 
| PRODUCT HIGHLIGHTS USIM Reader 1 EA 
USB Hub 1 EA 
= ~MD-NEXT/MD-RED pre-installed laptop Portable Printer 1 EA (option) 


= All-in-one mobile forensic package for the investigation at the field 


Warranty 1 Year 
= Customizable package components 


MD-RUGGED 
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MD-PORTABLE 


MD-PORTABLE supports to quickly respond to the field request by a faster and selective collection of the evidence data using MD-LIVE. Perform 
as a mobile evidence triage and supports selective acquisition for privacy protection. 


| KEY FEATURES 


Portable live forensic tool for the on site investigator 


- Portable tablet with MD-LIVE software allows quick response at the crime scene onsite and data acquisition on the move 


Supports faster and secured forensic process 


- Fast acquisition of selective data using MD-LIVE to secure the privacy of phone owner 


Mirroring and remote control of smartphone display 
- Can be used when phone screen is broken and it prevents unwanted operation occuring on the phone 
* The mirrored screen can be captured and also recorded as an evidence 

Screen recording of MD-LIVE software 


* PC screen of MD-LIVE recording to reproducing and verify its forensic process 


External camera for Chain of Custody 


* Photographing evidence and recording of investigation process with external camera for Chain of Custody 


Supports all the necessary live forensic accessories 


- USB cables, External camera, Tablet, Portable carrier 


Mobile forensic portable package with MD-LIVE for the first responder or triage at the crime scene 


Package components Tablet specification 
Portable Carrier 1 EA OS: Windows 8/10 (All 64bit) 
D-LIVE Installation Software (USB/Online) CPU: i5 or faster 

SPEC | FICATION USB Dongle Key 1 EA RAM: 8GB 
Touch Tablet 1 EA SSD: 512G 
5 Types of smartphone cables (5, 8, 20, 30, C-typed pin) Display: 1024x768 or higher 

| PRODUCT HIGHLIGHTS HD External Camera 1 EA USB: 1 or more USB 2.0/3.0/3.1 ports 
Portable Printer 1 EA (option) Microsoft Net Framework 4.5 

= MD-LIVE pre-installed tablet Warranty 1 Year 

a All-in-one package for the first responder in the field 


= Customizable package components 
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MD-ACADEMY 


MD-ACADEMY is the complete set of mobile forensic tools customized for mobile forensic education. 


MD-ACADEMY is composed of the test materials and the academic version of MD-NEXT, MD-RED for in-depth mobile forensic training 
and education of the latest mobile forensic technology. 


| KEY FEATURES 


Provides complete set of mobile forensic training 


- Tutorial for training such as basic theory, and practice guide 
- Academic version of MD-NEXT 
- Academic version of MD-RED 


Designed for practical mobile forensic practice 


- Provides samples for mobile forensic training; Smartphone/Memory/Data readers 


Designed for practical data analysis training 


- Provides sample data for data analysis training 


User customized package set 


- MD-ACADEMY package can be customized by user numbers (1/5/10/20 users) 


Package components Optional components 
Complete set of mobile forensic tools customized for education and training 
MD-ACADEMY Carrier for 1/5/10/20 users’ package MD-READER demo set 
MD-NEXT, MD-RED (Academic version) Textbook copies 
S D -CI F | CATI O NI USB Dongle Keys (1/5/10/20 users) Training video 
Samples of USIM Cards Samples of test phones 
Samples of SD Cards Samples of Chip-off memory 
| PRODUCT HIGHLIGHTS SD Memory Readers 
USIM Readers 


= Provides academic version of MD-NEXT and MD-RED = Provides complete set of academic tutorial 
= License and materials set for 1,5, 10, 20 users 
= Provides various data readers - SD reader/USIM reader/Chip-off 
memory reader 
= Customizable package components 


5 Types of smartphone cables (5, 8, 20, 30, C-typed pin) 
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T R A | N | N G & HancomWITH Certified Mobile Forensic Professional 
X HCMP certification will equip you with basic mobile forensics knowledge and teach you to make practical use of HancomWITH's 


mobile data extraction and analysis software. This certification is aimed at practitioners who are new to mobile forensics. Those 
Maximize your skills, knowledge and mobile forensic capabilities with HancomWITH 


who hold this certification are given the opportunity to advance their careers in the mobile forensics industry. 


-The basic theory of mobile forensics 
-Training for mobile forensic tools; MD-NEXT / MD-RED / MD-LIVE / MD-VIDEO 


; . : : : . ; So HancomWiITH Certified Mobile Forensic Examiner 
HancomWITH provides an extensive set of certified courses composed of certification courses, mobile forensic training 


courses, webinars and other training materials. Covering all levels of knowledge from beginner to expert, each course HCME 
provides students with a detailed understanding of mobile forensics as well as up-to-date forensic knowledge. If you are 
looking for an education in mobile forensics, our training team is waiting for you. Select a course suited to your level and 
obtain what you need here. 


HCME certification is designed to train mobile forensic examiners in the use of both HancomWITH's MD-Series hardware and 
£ GANTON ‘a software products. This certification deals with high level techniques for handling Android and iOS-based smartphone forensics 
E = : and various kinds of analysis methods. An HCME certification certifies that an examiner is equipped with a vast depth of 
understanding and expertise in the use of HancomWITH's complete mobile forensic solution. 


Physical data extraction Advanced mobile forensic 

- STAG forensics (MD-BOX) - Android/iOS Forensics 

- Chip-off forensics (MD-READER) - Database structure, SQLite, Filesystem 
- Memory removal (MD-MR) and Multimedia analysis 


HancomWITH Certified Mobile Forensic Specialist 


HCMS 


HCMS certification certifies that an examiner has successfully completed all the contents of the certification course and mastered 
in-depth mobile forensic investigative methodology. Recognized by investigative agencies as a skilled specialist in the mobile 
forensics sector, an HCMS certified examiner can manage matters of all sizes, including real-world application analysis based on 
Python scripting. 


Curriculum 


Advanced mobile forensic theory I! Python analysis scripting 

- SQLite analysis II - App analysis trends and issue 
- Filesystem analysis Il - Script programming basics 

- Multimedia analysis Il - Script programming API 

- Messenger decoding/decryption - Script programming practice 
- APK analysis 


- Reverse engineering 
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MOBILE & DIGITAL 
FORENSIC SERVICE 


HancomWITH provides one-stop forensic service for a law firm, audit, and eDiscovery corporation. 

It's comprehensive mobile and digital forensic service which includes evidence data acquisition from a Smartphone, 
Tablet, PC, CCTV/DVR, Drone, Car, loT device, Cloud service and data analysis on various mobile data, apps, videos, audios, 
documents and so on. Data analysis report and investigation consulting service are provided according to the specific 
client's inquiry. 


| Service Highlights 


Supports various kinds of 
mobile devices 


7~ 


HANTOM 


HANCOM WITH 


Recovery of deleted data and 
decryption of encrypted data 


Data extraction & analysis 


Provides investigation reports with the 
comments by mobile forensic experts 
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I Key Services 


One-stop mobile and digital forensic service 
A comprehensive forensic service that provides a complete forensic solution. It provides evidence data acquisition, 


01 data analysis from a wide range of mobile and digital devices, and analysis report, including entire process recording 
for a Chain of Custody. 
Unlock service & Data extraction 
Data extraction service including screen unlock and decryption for encrypted data partition from the Smartphone, 

02 Tablet, PC, CCTV/DVR, Drone, Car, IoT device, and Cloud service. It warrants the integrity of all extracted evidence 
data. 
Data analysis & Analysis report 

03 Analysis of extracted data, data recovery, decryption of encrypted data, and proivdes analysis reports. 

4 Forensic investigation support 

0 Provides a complete forensic investigation service according to the specific client's inquiry. 
Legal advisory service in terms of forensic investigation 

05 Being in partnership with law firms, we provide legal advice on security audit and all the consulting service related 
to forensic investigation. 
Customized service 

06 Provides customized forensic service according to each client's requirement, including corporate audit, corruption 


investigation, and an eDiscovery forensics. 


MOBILE & DIGITAL FORENSIC SERVICE 
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MOBILE FORENSIC 
LAB SOLUTION 


Fully equipped mobile forensic laboratory solution for forensic investigators to handle a 
massive variety of different mobile device safe and efficiently 


Our Mobile forensic lab is equipped with the all needed tools and hardware to identify, analyze, preserve, recover, and present facts 
and opinions about the information at hand efficiently. 

The Mobile forensic laboratory supports investigator to handle a vast variety of different mobile and digital device with reliable and 
efficient solutions. It will help your team to analyze evidence in the most efficient way and forensically sound manner. 


aE 


Fá 


y 


Physical rework desk Data extraction work desk 


- MD-READER/MD-BOX hardware 

* MD-MR package 

* MD-CARRIER package 

- MD-CABLESUITE for JTAG connection 
- USIM reader, SD reader 

- Air ventilation for soldering work 


Data analysis work desk 


- MD-RED, MD-VIDEO, MD-CLOUD Software 
- GPU Workstation/Workstation/Laptop 

- NAS storage rack 

- 10G network device 


- MD-NEXT software 
- MD-LIVE software 
- Workstation/Laptop/Tablet 


Laboratory management 


* Smartphone and tablet storage 
- Disk and flash memory storage 
- Video recording system 

- Lighting system 

* GPS system 
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